fix(test): hermetically exercise auth workflows

This commit is contained in:
2026-08-25 18:27:41 +02:00
parent 2c2bf1940b
commit db375298d0
5 changed files with 34 additions and 10 deletions
+3 -2
View File
@@ -142,9 +142,10 @@ test("OIDC Authorization Code plus PKCE redirects back and maps ordinary and adm
expect(stack.lastAuthorization()).toMatchObject({ codeChallengeMethod: "S256", pkceVerified: true });
await expectNoWebStorageTokens(page);
await page.getByRole("button", { name: "Log out", exact: true }).click();
await expect(page.getByRole("heading", { name: "Sign in to ThothII" })).toBeVisible();
await expect(page.getByRole("button", { name: "Log out", exact: true })).toHaveCount(0);
await page.context().clearCookies();
stack.setOidcIdentity("admin");
await page.goto(stack.publicUrl);
await signInWithOidc(page);
await expectShell(page);
expect((await browserSession(page)).body.roles).toEqual(["admin"]);
+9 -1
View File
@@ -354,6 +354,7 @@ export async function createAuthenticationStack({ withF1Workspace = false } = {}
const workspaceSecretRoot = join(root, "workspace-secrets");
const workspaceRuntimeRoot = join(root, "workspace-runtime");
const fixtureSecretRoot = join(root, "fixture-runtime-secrets");
const piAgentRoot = join(root, "pi-agent");
const providerRoot = join(root, "provider");
const authConfigFile = join(root, "auth.yaml");
const usersFile = join(root, "users.yaml");
@@ -363,8 +364,14 @@ export async function createAuthenticationStack({ withF1Workspace = false } = {}
const authStorageBinary = join(root, "tht-auth-storage");
const fixtureDwhPasswordFile = join(fixtureSecretRoot, "fixture-dwh-password");
const fixtureDwhCaFile = join(fixtureSecretRoot, "fixture-dwh-ca.pem");
for (const path of [stateRoot, registryRoot, workspaceSecretRoot, workspaceRuntimeRoot, fixtureSecretRoot, providerRoot]) secureDirectory(path);
for (const path of [stateRoot, registryRoot, workspaceSecretRoot, workspaceRuntimeRoot, fixtureSecretRoot, piAgentRoot, providerRoot]) secureDirectory(path);
for (const child of ["sessions", "oidc"]) secureDirectory(join(stateRoot, child));
writeSecure(join(piAgentRoot, "settings.json"), JSON.stringify({
enabledModels: ["zai/glm-5.2"],
}));
writeSecure(join(piAgentRoot, "auth.json"), JSON.stringify({
zai: { type: "api_key", key: "e2e-model-key-not-a-production-secret" },
}));
const [frontendPort, backendPort] = await Promise.all([freeLoopbackPort(), freeLoopbackPort()]);
const publicUrl = `http://127.0.0.1:${frontendPort}`;
@@ -494,6 +501,7 @@ export async function createAuthenticationStack({ withF1Workspace = false } = {}
HOST: "127.0.0.1",
PORT: String(backendPort),
PI_BIN: fakePi,
PI_CODING_AGENT_DIR: piAgentRoot,
THT_BIN: fakeTht,
THT_AUTH_STORAGE_BIN: authStorageBinary,
THT_HARNESS_DIR: harnessRoot,